Who Sets the Standards for AI Agent Payments? The Bodies, the Specs, the Status (2026)
Short answer: There is no single standards body for AI-agent payments. As of September 2026, governance splits three ways: two specs have moved to genuinely independent, multi-company stewards (x402 → the Linux-Foundation-hosted x402 Foundation; AP2 → the FIDO Alliance); one has been submitted to the IETF as an Internet-Draft (MPP), which its stewards describe as the standards track; and the rest — ACP, UCP, Visa's Trusted Agent Protocol, Mastercard Agent Pay, and MCP's own specification — are still run by the company or companies that created them, with varying degrees of openness (open-source repos, Apache-2.0 licences, public issue trackers) but no independent foundation holding the pen. No two specs use the same governance model, and none has a shared, cross-spec definition of a spending limit.
Last updated 2026-09-30. Every claim below is sourced from the governing body's own site, blog, press release or GitHub repository, checked on the date noted; GitHub-hosted claims are pinned to a specific commit SHA so they stay reproducible.
The steward table
| Spec | Steward / governing body | Type | Openness | Status / version | Last governance change |
|---|---|---|---|---|---|
| x402 | x402 Foundation (hosted by the Linux Foundation) | Foundation | Apache-2.0, github.com/x402-foundation/x402 | Active; V2 launched, "processed over 100M payments" | Operational launch, 40 member orgs — 2026-07-14 (Linux Foundation) |
| AP2 (Agent Payments Protocol) | FIDO Alliance | Foundation (industry association) | Apache-2.0, github.com/google-agentic-commerce/AP2 (repo not yet renamed) | Active spec + reference SDK; open issues/PRs unmerged as of 2026-09-29 | Donated by Google to FIDO Alliance — 2026-04-28 (Google blog) |
| ACP (Agentic Commerce Protocol) | OpenAI and Stripe, as "Founding Maintainers" | Multi-company (two) | Apache-2.0, github.com/agentic-commerce-protocol/agentic-commerce-protocol | Beta | Repo README states "a clear path toward broader community governance" — no independent foundation yet; launched 2025-09-29 (Stripe newsroom) |
| MPP (Machine Payments Protocol) | Co-authored by Tempo and Stripe; core spec submitted to the IETF standards track | Multi-company origin → standards body (in progress) | Spec text under IETF Trust licensing (BCP 78/79); code under Revised BSD; spec repo github.com/tempoxyz/mpp-specs | IETF Internet-Draft, draft-httpauth-payment |
Announced by Stripe/Tempo — 2026-03-18 (Stripe blog); IETF draft tracked at datatracker.ietf.org |
| UCP (Universal Commerce Protocol) | Google, with Shopify, Etsy, Wayfair, Target and Walmart named as collaborators | Multi-company (Google-led) | Apache-2.0, github.com/universal-commerce-protocol/ucp | "Open-source standard," no independent foundation named | Announced — 2026-01-11 (Google Developers blog) |
| MCP (Model Context Protocol) | "Model Context Protocol a Series of LF Projects, LLC" (Linux Foundation) | Foundation, individual-membership governance | Code/spec under Apache-2.0; docs under CC BY 4.0 (governance page) | Spec version 2025-11-25 |
First-anniversary spec release; steering group of 2 Lead Maintainers + 6 Core Maintainers — 2025-11-25 (MCP blog) |
| Visa Trusted Agent Protocol (TAP) | Visa, developed with Cloudflare | Single company + one co-developer | Visa states it wants to align with "IETF, OpenID Foundation and EMVCo," but no independent body governs TAP itself yet; spec published on Visa Developer Center and GitHub | Announced | Launched — 2025-10-14 (Visa newsroom) |
| Mastercard Agent Pay | Mastercard, with named partners (Microsoft, IBM, Braintree, Checkout.com) for specific use cases | Single company | No public spec repo or licence found; partnership-based, not an open spec | Announced (April 2025), extended as "Agent Pay for Machines" (June 2026) | Original unveiling — 2025-04-29 (Mastercard newsroom) |
Company-led specs
ACP is the clearest example of a two-company protocol that hasn't yet handed governance to a third party. Its own README says: "ACP is jointly governed by OpenAI and Stripe as Founding Maintainers, with a clear path toward broader community governance" (agentic-commerce-protocol/agentic-commerce-protocol, commit 7fdd78d, README.md). Changes go through a "SEP" (Stripe Enhancement Proposal) process and require a signed Contributor License Agreement; the repo is Apache-2.0 and the spec is marked "beta" via its own status badge. ACP launched alongside ChatGPT's Instant Checkout on 2025-09-29, with Etsy as the first integrated merchant (Stripe newsroom); PayPal (2025-10-28) and Checkout.com (2025-11-25) later adopted it.
UCP follows a similar single-lead-company pattern: Google's developer blog describes it as "an open-source standard designed to power the next generation of agentic commerce," "developed by Google in collaboration with industry leaders including Shopify, Etsy, Wayfair, Target, and Walmart" (Google Developers blog). The spec repo (github.com/universal-commerce-protocol/ucp) is Apache-2.0, but no separate foundation or member list beyond the launch partners has been published as of this writing.
Visa's Trusted Agent Protocol and Mastercard Agent Pay are card-network programs rather than open specs in the ACP/UCP sense — see below.
Foundations and industry bodies
Two protocols have moved from a single corporate owner to something closer to independent governance, and one is on an actual standards-development-organization track:
- x402 was contributed by Coinbase, then handed to a purpose-built nonprofit. On 2025-09-23, Cloudflare wrote: "Cloudflare is partnering with Coinbase to create the x402 Foundation. This foundation's mission will be to encourage the adoption of the x402 protocol" (Cloudflare blog). The Linux Foundation announced the foundation's operational launch on 2026-07-14, noting "40 organizations have joined as members" (Linux Foundation press release). The spec and reference implementation live at github.com/x402-foundation/x402 under Apache-2.0.
- AP2 was Google's protocol until Google "donat[ed] the Agent Payments Protocol (AP2) to the FIDO Alliance" on 2026-04-28, saying the move "ensures AP2 remains platform-agnostic and community-led" (Google blog). The reference repo, still hosted at
google-agentic-commerce/AP2and Apache-2.0 licensed, had multiple open, unmerged issues and PRs as of 2026-09-29 — governance transferred, but the codebase hasn't fully moved yet. - MPP's core spec is not run by a foundation at all — it went straight to a standards-development organization. mpp.dev's own governance page states the core specification "is published as the Payment HTTP Authentication Scheme and submitted to the IETF standards track, where it continues to progress as an open, vendor-neutral standard," and that "payment rails and third parties do not need explicit approval to add a payment method implementation to MPP" (mpp.dev/governance). The draft is tracked publicly as
draft-httpauth-paymenton the IETF Datatracker; the core spec repo is github.com/tempoxyz/mpp-specs. - MCP (the connector protocol payment MCP servers run on, not a payment protocol itself) is legally structured as "Model Context Protocol a Series of LF Projects, LLC," under the Linux Foundation (governance page). It uses a hierarchical, individual (not company) membership model — Lead Maintainers ("BDFL"), Core Maintainers, Maintainers, Contributors — with code/spec under Apache-2.0 and non-spec docs under CC BY 4.0. Its most recent spec version,
2025-11-25, shipped on MCP's first anniversary alongside a steering-group structure of 2 Lead Maintainers and 6 Core Maintainers (MCP blog).
Card networks
Visa and Mastercard have each announced agent-payment programs, but neither has published an independently governed open spec the way x402, AP2 or MPP have.
Visa's Trusted Agent Protocol (TAP), announced 2025-10-14, was "developed in collaboration with Cloudflare," with the press release naming "insightful feedback from other early partners including Adyen, Ant International, Checkout.com, Coinbase, CyberSource, Elavon, Fiserv, Microsoft, Nuvei, Shopify, Stripe and Worldpay" and stating Visa is "committed to aligning closely with global standards bodies like IETF, OpenID Foundation and EMVCo" (Visa newsroom). That alignment is a stated intent, not evidence that IETF, OpenID Foundation or EMVCo currently govern TAP.
Mastercard Agent Pay, unveiled 2025-04-29, gives "[c]onsumers ... complete control over what the agent is allowed to purchase on their behalf" (Mastercard newsroom) and named Microsoft and IBM as use-case partners. Mastercard extended the program to machine-to-machine payments as "Agent Pay for Machines" in June 2026. Neither TAP nor Agent Pay has a public spec repository comparable to ACP's, UCP's or AP2's.
What's not standardised yet
Even among specs that do publish schemas, there is no shared field for "how much can this agent spend." A cross-provider crosswalk of 14 payment providers/protocols — including AP2, x402, Visa Intelligent Commerce and Mastercard Agent Pay — found that "[e]very payment provider and protocol that lets you cap what an AI agent can spend uses its own field names, units, and enforcement point — there is no shared standard" (Agent Spending Controls Crosswalk). The same dataset notes that, as of 2026-09-29, "Visa Intelligent Commerce and Mastercard Agent Pay ... neither had a public developer reference with a concrete field name for a spend-limit parameter." Separately, AP2's own schema has an internal unit mismatch — one field documented in minor units (cents), a related field with no unit stated at all, reconciled only by reading the reference SDK's source code.
Timeline of governance moves
- 2025-09-23 — Cloudflare announces it is partnering with Coinbase to create the x402 Foundation (Cloudflare blog)
- 2025-09-29 — OpenAI and Stripe release ACP and launch ChatGPT Instant Checkout with Etsy (Stripe newsroom)
- 2025-11-25 — MCP Steering Committee ships spec version
2025-11-25on MCP's first anniversary (MCP blog) - 2026-01-11 — Google announces UCP with Shopify, Etsy, Wayfair, Target and Walmart (Google Developers blog)
- 2026-03-18 — Stripe and Tempo announce MPP, submitted to the IETF standards track (Stripe blog)
- 2026-04-28 — Google donates AP2 to the FIDO Alliance (Google blog)
- 2026-07-14 — x402 Foundation's operational launch, 40 member organizations (Linux Foundation)
Full 30-event dataset, each with a primary-source URL and quote: awesome-agentic-payments/TIMELINE.md.
FAQ
Is there one standards body for AI agent payments? No. Governance is split across at least three models: independent foundations (x402 Foundation, FIDO Alliance for AP2, Linux Foundation for MCP), an Internet-Draft submitted to a standards-development organization (MPP at the IETF), and company-led specs with open-source repos but no independent steward (ACP, UCP, Visa TAP, Mastercard Agent Pay).
Which agent-payment spec is furthest along a neutral, multi-stakeholder path? By foundation status, x402 (Linux-Foundation-hosted, 40 member organizations as of 2026-07-14) and AP2 (donated to the FIDO Alliance on 2026-04-28) are the two that have formally exited single-company control. MPP is notable for skipping a foundation step entirely and going straight to an IETF Internet-Draft.
Do any of these specs define a common way to cap agent spending? Not across specs. Each protocol that supports spend limits (AP2, x402, Visa Intelligent Commerce, Mastercard Agent Pay, and others) uses its own field names and enforcement point; a cross-provider crosswalk found no shared schema for amount caps, allowlists or approval thresholds (Agent Spending Controls Crosswalk).
Is the Model Context Protocol (MCP) itself a payment standard? No. MCP is the general connector standard (governed by "Model Context Protocol a Series of LF Projects, LLC," under the Linux Foundation) that lets an AI assistant call external tools and services — including payment MCP servers built by companies like Adyen, Razorpay, Mollie and Stripe. It doesn't itself define how a payment or spending limit is represented.
Pink Agentic AI Payment (early access) enforces per-agent spending caps, allowlists and approval thresholds at the MCP layer, before a payment executes.
This guide is published by PinkWallet, which is building Pink Agentic AI Payment (early access). We are not neutral in this space, which is why every factual claim links to a primary source.






